Last reviewed: May 1, 2026
Listen now
How do measures and metrics differ, and why is this distinction crucial for FDA submissions?
In this episode, Christian and Trevor demystify the difference between cybersecurity measures and metrics in the context of FDA guidance. They explore what the FDA expects in submissions, emphasizing patch timelines, vulnerability tracking, and post-market data collection. They also discuss the importance of actionability over mere compliance and include real-world challenges like device downtime and risk in different environments.
Key points:
(0:30) Measures vs Metrics Defined
- Measures are raw figures like time or count; metrics are calculated from measures.
(4:06) FDA Guidance and Patch Timelines
- FDA expects metrics like percentage of patched vulnerabilities and two patch-related durations.
(7:49) Real-Time Alerts
- Devices should notify users immediately of anomalies to compensate for lack of SOC monitoring.
(14:01) When to Include Metrics in Submissions
- Metrics aren’t always required during initial submission unless data is available.
(18:07) Downtime, Rebooting, and Risk Profiles
-
Reboot times and system recovery durations should be treated as key measures.
-
Risk profiles shift based on device use environment.
Bring this work to your device
Need help with fda premarket cybersecurity?
Blue Goat Cyber delivers fda premarket cybersecurity services for medical device manufacturers - from threat modeling to FDA-ready reports.
FDA Premarket Cybersecurity ServicesMore on FDA Premarket Cybersecurity
Keep listening
-
Episode 69
Science Before Hype in MedTech Investing with Varun Turlapati of Chaanakya Capital
With Varun Turlapati
-
Episode 67
De-Risking Product Decisions in MedTech Startups with Brent Lavin of Ironwood MedTech Partners
With Brent Lavin
-
Episode 65
Why Clinical Trials Are the Most Expensive Capital Outlay for Startups with Rob Bedford, CEO of Franklyn Health
With Rob Bedford
-
Episode 64
Traceability Requirements and Documentation Audit Trails with Dr. Basant Bajpai, CEO of Compliance MedQRA
With Dr. Basant Bajpai